Escan/english/escan20/firewall: Difference between revisions

From eScan Wiki
Jump to navigation Jump to search
imported>TechContent
No edit summary
imported>TechContent
No edit summary
Line 20: Line 20:
<h5 style='color:#0276FD;font-size:16.0pt;font-family:"Open Sans"'>Expert Rule</h5>
<h5 style='color:#0276FD;font-size:16.0pt;font-family:"Open Sans"'>Expert Rule</h5>


<p class=MsoNormal style='margin-bottom:0in'><span lang=EN-IN style='color:
<p style='font-size:11.0pt;font-family:"Open Sans"'>This tab allows you to specify advanced rules and settings for the firewall. You can configure expert rules on the basis of the various rules, protocols, source IP address and port, destination IP address and port, and ICMP types. You can create new expert rules. However, you should configure these rules only if you have a good understanding of firewalls and networking protocols.</p>
black'>This tab allows you to specify advanced rules and settings for the
firewall. You can configure expert rules on the basis of the various rules,
protocols, source IP address and port, destination IP address and port, and
ICMP types. You can create new expert rules. However, you should configure
these rules only if you have a good understanding of firewalls and networking
protocols</span><span lang=EN-IN>.</span></p>


<p class=MsoNormal align=center style='margin-top:12.0pt;text-align:center'><img
<p style='font-size:11.0pt;font-family:"Open Sans"'>This tab has various button and settings:</p>
border=0 width=624 height=442 src="TSS%20UG%20v20_reviewed_files/image062.jpg"></p>


<p class=MsoNormal style='margin-bottom:0in;text-align:justify'><span
<ul >
lang=EN-IN style='color:black'>This tab has various button and settings:</span></p>
  <li style='font-size:11.0pt;font-family:"Open Sans"'><b>Add</b>: This button adds new rules. We will see how to add new rule in the following <i> Adding New Rule</i> section. </li>
 
  <li style='font-size:11.0pt;font-family:"Open Sans"'><b>Modify</b>: This button modifies the already existing rules in the list.</li>
<ul style='margin-top:0in' type=disc>
  <li style='font-size:11.0pt;font-family:"Open Sans"'><b>Remove</b>: This button removes the existing rules from the list.</li>
  <li class=MsoNormal style='color:black;margin-bottom:0in;margin-bottom:0in;
  <li style='font-size:11.0pt;font-family:"Open Sans"'><b>Default</b>: This button resets the all the configuration settings.</li>
    margin-top:0in;text-align:justify'><b>Add</b>: This button adds new rules.
  <li style='font-size:11.0pt;font-family:"Open Sans"'><b>Green arrow buttons</b>: This buttons can be used to prioritize the expert rule based on the specific need of the user.</li>
    To learn more, <span style='color:#00B050'><a href="#_Adding_new_rule"><span
    style='color:#00B050'>click here</span></a></span>.</li>
  <li class=MsoNormal style='color:black;margin-bottom:0in;margin-bottom:0in;
    margin-top:0in;text-align:justify'><b>Modify</b>: This button modifies the
    already existing rules in the list.</li>
  <li class=MsoNormal style='color:black;margin-bottom:0in;margin-bottom:0in;
    margin-top:0in;text-align:justify'><b>Remove</b>: This button removes the
    existing rules from the list.</li>
  <li class=MsoNormal style='margin-bottom:0in'><b><span lang=EN-IN
    style='color:black'>Default</span></b><span lang=EN-IN style='color:black'>:
    This button resets the all the configuration settings.</span></li>
  <li class=MsoNormal style='margin-bottom:0in'><b><span lang=EN-IN>Green arrow
    buttons</span></b><span lang=EN-IN>: This buttons can be used to
    prioritize the expert rule based on the specific need of the user.</span></li>
</ul>
</ul>


<span lang=EN-IN style='font-size:11.0pt;line-height:115%;font-family:"Open Sans",sans-serif'><br
<p style='color:#0276FD;font-size:14.0pt;font-family:"Open Sans"'>Adding new rule</b></p>
clear=all style='page-break-before:always'>
</span>


<p class=MsoNormal><a name="_Adding_new_rule"></a><b><span lang=EN-IN
<p style='font-size:11.0pt;font-family:"Open Sans"'>This section will describe how to add new rule. Click on <b>Add </b>button, Add Firewall Rule window appears.</p>
style='font-size:12.0pt;line-height:115%'>Adding new rule</span></b></p>
<br>
<p style='color:#0276FD;font-size:12.0pt;font-family:"Open Sans"'><b>General</b></p>


<p class=MsoNormal style='margin-bottom:0in'><span lang=EN-IN>This section will
<p style='font-size:11.0pt;font-family:"Open Sans"'>This tab enables you to define rules and its actions. Specify the following field details:</p>
describe how to add new rule. Click on <b>Add </b>button, Add Firewall Rule
<ul>
window appears.</span></p>
<li style='font-size:11.0pt;font-family:"Open Sans"'> <b> Rule Name<</b>: Type the rule name.</li>
 
<li style='font-size:11.0pt;font-family:"Open Sans"'><b>Rule Action</b>: Click any one of the following types of actions for setting rules. </p>
<p class=MsoNormal align=center style='margin-top:12.0pt;text-align:center'><img
<ul>
border=0 width=392 height=530 src="TSS%20UG%20v20_reviewed_files/image063.png"></p>
<li style='font-size:11.0pt;font-family:"Open Sans"'><b>Permit Packet</b>: This option is selected by default and it allows you to permit packets.</li>
 
<li style='font-size:11.0pt;font-family:"Open Sans"'> <b>Deny Packet</b>: This option allows you to deny packets.</li>
<p class=MsoNormal style='margin-bottom:0in'><b><span lang=EN-IN
</ul>
style='font-size:12.0pt;line-height:115%;color:black'>General</span></b></p>
<li style='font-size:11.0pt;font-family:"Open Sans"'><b>Protocol</b>: This option lets you to select an appropriate type of protocol from the drop-down list. By default, <b>TCP and UDP</b> is selected.</li>
 
<li style='font-size:11.0pt;font-family:"Open Sans"'><b>Apply Rule On Interface</b>: This option lets you to select Interface to apply the rule. By default, <b>Any Interface</b> is selected.</li>
<p class=MsoNormal style='margin-bottom:0in;text-align:justify;line-height:
normal'><span style='color:black'>This tab enables you to define rules and its
actions. Specify the following field details:</span></p>
 
<p class=MsoNormal style='margin-top:0in;margin-right:0in;margin-bottom:0in;
margin-left:.5in;text-align:justify;text-indent:-.25in;line-height:normal'><span
style='font-family:Symbol;color:black'>·<span style='font:7.0pt "Times New Roman"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span><b><span style='color:black'>Rule Name</span></b><span
style='color:black'>: Type the rule name.</span></p>
 
<p class=MsoNormal style='margin-top:0in;margin-right:0in;margin-bottom:0in;
margin-left:.5in;text-align:justify;text-indent:-.25in;line-height:normal'><span
style='font-family:Symbol;color:black'>·<span style='font:7.0pt "Times New Roman"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span><b><span style='color:black'>Rule Action</span></b><span
style='color:black'>: Click any one of the following types of actions for
setting rules. </span></p>
 
<p class=MsoNormal style='margin-top:0in;margin-right:0in;margin-bottom:0in;
margin-left:1.0in;text-align:justify;text-indent:-.25in;line-height:normal'><span
style='font-family:"Courier New";color:black'>o<span style='font:7.0pt "Times New Roman"'>&nbsp;&nbsp;
</span></span><b><span style='color:black'>Permit Packet</span></b><span
style='color:black'>: This option is selected by default and it allows you to
permit packets.</span></p>
 
<p class=MsoNormal style='margin-top:0in;margin-right:0in;margin-bottom:0in;
margin-left:1.0in;text-align:justify;text-indent:-.25in;line-height:normal'><span
style='font-family:"Courier New";color:black'>o<span style='font:7.0pt "Times New Roman"'>&nbsp;&nbsp;
</span></span><b><span style='color:black'>Deny Packet</span></b><span
style='color:black'>: This option allows you to deny packets.</span></p>
 
<p class=MsoNormal style='margin-top:0in;margin-right:0in;margin-bottom:0in;
margin-left:.5in;text-align:justify;text-indent:-.25in;line-height:normal'><span
style='font-family:Symbol;color:black'>·<span style='font:7.0pt "Times New Roman"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span><b><span style='color:black'>Protocol</span></b><span
style='color:black'>: This option lets you to select an appropriate type of protocol
from the drop-down list. By default, <b>TCP and UDP</b> is selected.</span></p>
 
<ul style='margin-top:0in' type=disc>
<li class=MsoNormal><b><span lang=EN-IN style='color:black'>Apply Rule On
    Interface</span></b><span lang=EN-IN style='color:black'>: This option
    lets you to select Interface to apply the rule. By default, <b>Any
    Interface</b> is selected.</span></li>
</ul>
</ul>
<br>
<p style='color:#0276FD;font-size:12.0pt;font-family:"Open Sans"'>Source</b></p>


<b><span lang=EN-IN style='font-size:12.0pt;line-height:115%;font-family:"Open Sans",sans-serif;
<p style='font-size:11.0pt;font-family:"Open Sans"'>This tab enables you to type the source IP address and port wherever applicable. You can select the appropriate option. By default, <b>My Network</b> under <b>Source IP Address</b> section and <b>Any</b> under <b>Source Port</b> section are selected.</p>
color:black'><br clear=all style='page-break-before:always'>
</span></b>
 
<p class=MsoNormal style='margin-bottom:0in'><b><span lang=EN-IN
style='font-size:12.0pt;line-height:115%;color:black'>Source</span></b></p>
 
<p class=MsoNormal style='margin-bottom:0in'><span lang=EN-IN style='color:
black'>This tab enables you to type the source IP address and port wherever
applicable. You can select the appropriate option. By default, <b>My Network</b>
under <b>Source IP Address</b> section and <b>Any</b> under <b>Source Port</b>
section are selected.</span></p>
 
<p class=MsoNormal align=center style='margin-top:12.0pt;text-align:center'><img
border=0 width=392 height=530 src="TSS%20UG%20v20_reviewed_files/image064.png"></p>
 
<b><span lang=EN-IN style='font-size:12.0pt;line-height:115%;font-family:"Open Sans",sans-serif;
color:black'><br clear=all style='page-break-before:always'>
</span></b>
 
<p class=MsoNormal style='margin-bottom:0in'><b><span lang=EN-IN
style='font-size:12.0pt;line-height:115%;color:black'>Destination</span></b></p>
 
<p class=MsoNormal style='margin-bottom:0in'><span lang=EN-IN style='color:
black'>This tab enables you to type the destination IP address and port wherever
applicable.  You can select the appropriate option. By default, <b>My Network</b>
under <b>Destination IP Address</b> section and <b>Any</b> under <b>Destination</b>
<b>Port</b> section are selected.</span></p>
 
<p class=MsoNormal align=center style='margin-top:12.0pt;text-align:center'><img
border=0 width=392 height=530 src="TSS%20UG%20v20_reviewed_files/image065.png"></p>
 
<b><span lang=EN-IN style='font-size:12.0pt;line-height:115%;font-family:"Open Sans",sans-serif;
color:black'><br clear=all style='page-break-before:always'>
</span></b>
 
<p class=MsoNormal style='margin-bottom:0in'><b><span lang=EN-IN
style='font-size:12.0pt;line-height:115%;color:black'>Advanced</span></b></p>
 
<p class=MsoNormal style='margin-bottom:0in'><span lang=EN-IN style='color:
black'>This tab is specifically meant for ICMP processing, the fields on this
tab are available only when you select ICMP from <b>Protocol</b> drop-down
list, under <b>General</b> </span><span lang=EN-IN>tab.</span></p>
 
<p class=MsoNormal align=center style='margin-top:12.0pt;text-align:center'><a><img
border=0 width=392 height=530 src="TSS%20UG%20v20_reviewed_files/image066.png"></a><span
class=MsoCommentReference><span lang=EN-IN style='font-size:8.0pt;line-height:
115%'><a class=msocomanchor id="_anchor_4"
onmouseover="msoCommentShow('_anchor_4','_com_4')"
onmouseout="msoCommentHide('_com_4')" href="#_msocom_4" language=JavaScript
name="_msoanchor_4">[S4]</a>&nbsp;</span></span></p>


<p class=MsoNormal style='margin-top:12.0pt;margin-right:0in;margin-bottom:
<p style='color:#0276FD;font-size:12.0pt;font-family:"Open Sans"'>Destination</span></b></p>
0in;margin-left:0in'><span lang=EN-IN>After configuring all the tab according
to your need, click on <b>OK </b>to add the new rule. It will be added in the
list.</span></p>


<span lang=EN-IN style='font-size:14.0pt;line-height:115%;font-family:"Open Sans",sans-serif;
<p style='font-size:11.0pt;font-family:"Open Sans"'>This tab enables you to type the destination IP address and port wherever applicable.  You can select the appropriate option. By default, <b>My Network</b> under <b>Destination IP Address</b> section and <b>Any</b> under <b>Destination</b> <b>Port</b> section are selected.</p>
color:#00B050'><br clear=all style='page-break-before:always'>
</span>


<h5><span lang=EN-IN>Application Rule</span></h5>
<p style='color:#0276FD;font-size:12.0pt;font-family:"Open Sans"'>Advanced</b></p>


<p class=MsoNormal style='margin-bottom:0in'><span lang=EN-IN style='color:
<p style='font-size:11.0pt;font-family:"Open Sans"'>This tab is specifically meant for ICMP processing, the fields on this tab are available only when you select ICMP from <b>Protocol</b> drop-down list, under <b>General</b> tab.</p>
black'>An application rule is based on programs or applications that are
<p style='font-size:11.0pt;font-family:"Open Sans"'>After configuring all the tab according to your need, click on <b>OK </b>to add the new rule. It will be added in the list.</p>
allowed to or denied access to the internet or any network‑based service. The <b>Application
Rule</b> tab provides you with a default list of rules by eScan and options for
configuring application </span><span lang=EN-IN>rules.</span></p>


<p class=MsoNormal align=center style='margin-top:12.0pt;text-align:center'><img
<h5 style='color:#0276FD;font-size:16.0pt;font-family:"Open Sans"'>Application Rule</h5>
border=0 width=624 height=442 src="TSS%20UG%20v20_reviewed_files/image067.jpg"></p>


<p style='font-size:11.0pt;font-family:"Open Sans"'>An application rule is based on programs or applications that are allowed to or denied access to the internet or any network‑based service. The <b>Application Rule</b> tab provides you with a default list of rules by eScan and options for configuring application rules.</p>
<p class=MsoNormal style='margin-bottom:0in;text-align:justify'><span
<p class=MsoNormal style='margin-bottom:0in;text-align:justify'><span
lang=EN-IN style='color:black'>The context menu shows the following additional
lang=EN-IN style='color:black'>The context menu shows the following additional

Revision as of 11:02, 26 April 2021

Settings

You can configure the firewall setting here. When you click this option, the Firewall Settings (xxx) window appears. The xxx indicates the name of a tab. By default, Zone Rule tab appears. On the Firewall Settings (xxx) window, you have five tabs Zone Rule, Expert Rule, Application Rule, Trusted MAC Address, and Local IP List. Lets discuss them in detail.

Zone Rule

This tab helps you configure network access rules that specify which IP address, host name, or IP range of computers can access your computer.

This tab includes the following buttons:

  • Add Host Name: This button is used to add a zone rule for a given host. To add the zone rule, you must provide name of the host for which you are adding the zone rule; the type of zone, whether it is Trusted or Blocked and specify a name for the zone rule. Clicking OK will add the host in zone rule.
  • Add IP: This button is used to add a zone rule for a given IP address. To add the zone rule, you must provide the IP address for which you are adding the zone rule, the type of zone, whether it is Trusted or Blocked and specify a name for the zone rule. By selecting IPv6 Address check box you will enable IPv6 Protocol.
  • Add IP Range: This button is used to add a zone rule for a range of IP addresses. To add the zone rule, you must provide the range of IP address for which you are adding the zone rule, start IP address in the range, end IP address in the range; the type of zone, whether it is Trusted or Blocked and specify a name for the zone rule. This has 2 buttons, namely, OK to save changes and Cancel to exit the popup window.
  • Modify: This button is used to modify zone rules related to the host name, IP address, or range of IP addresses which is already added in the list. By selecting IPv6 Address check box you will enable Internet Protocol.
  • Remove: This button is used to remove the record from list.
  • Default: This button is used to load default settings.


Expert Rule

This tab allows you to specify advanced rules and settings for the firewall. You can configure expert rules on the basis of the various rules, protocols, source IP address and port, destination IP address and port, and ICMP types. You can create new expert rules. However, you should configure these rules only if you have a good understanding of firewalls and networking protocols.

This tab has various button and settings:

  • Add: This button adds new rules. We will see how to add new rule in the following Adding New Rule section.
  • Modify: This button modifies the already existing rules in the list.
  • Remove: This button removes the existing rules from the list.
  • Default: This button resets the all the configuration settings.
  • Green arrow buttons: This buttons can be used to prioritize the expert rule based on the specific need of the user.

Adding new rule

This section will describe how to add new rule. Click on Add button, Add Firewall Rule window appears.


General

This tab enables you to define rules and its actions. Specify the following field details:

  • Rule Name<: Type the rule name.
  • Rule Action: Click any one of the following types of actions for setting rules.

    • Permit Packet: This option is selected by default and it allows you to permit packets.
    • Deny Packet: This option allows you to deny packets.
  • Protocol: This option lets you to select an appropriate type of protocol from the drop-down list. By default, TCP and UDP is selected.
  • Apply Rule On Interface: This option lets you to select Interface to apply the rule. By default, Any Interface is selected.


Source

This tab enables you to type the source IP address and port wherever applicable. You can select the appropriate option. By default, My Network under Source IP Address section and Any under Source Port section are selected.

Destination

This tab enables you to type the destination IP address and port wherever applicable.  You can select the appropriate option. By default, My Network under Destination IP Address section and Any under Destination Port section are selected.

Advanced

This tab is specifically meant for ICMP processing, the fields on this tab are available only when you select ICMP from Protocol drop-down list, under General tab.

After configuring all the tab according to your need, click on OK to add the new rule. It will be added in the list.

Application Rule

An application rule is based on programs or applications that are allowed to or denied access to the internet or any network‑based service. The Application Rule tab provides you with a default list of rules by eScan and options for configuring application rules.

The context menu shows the following additional options when you right-click any rule in the table:

  • Add: Use this option to add new application to the Application Rule list.

<img border=0 width=436 height=275 src="TSS%20UG%20v20_reviewed_files/image068.png">


 

  • Remove: This option is used to remove any application from the Application Rule list.
  • Ask: This option is used to ask for your permission to permit or deny network access.
  • Permit: This option is used to permit any added Application for network access.
  • Deny: This option is used to deny network access to any application present in the Application Rule list.
  • Default: This option is used to reset the configuration to the default.
  • Process Properties: This option displays the properties of the selected process or file, which include the name of the file, owner of the file, copyright information, version, and path of the file.

<img border=0 width=435 height=290 src="TSS%20UG%20v20_reviewed_files/image069.png">


Trusted MAC Address

This section contains a list of Trusted Mac Addresses. A Mac address is a hardware address that uniquely identifies each node of a network.

<img border=0 width=624 height=442 src="TSS%20UG%20v20_reviewed_files/image070.jpg">

This tab has 4 buttons which are as follows:

  • Add: You can add new Mac address using this button. Once this button is clicked, you will see a New MAC Address dialogue box. Enter the MAC Address and Comment in this dialogue box and click OK.

<img border=0 width=361 height=200 src="TSS%20UG%20v20_reviewed_files/image071.png">

·         Edit: This button edits the existing entries in the list.

·         Remove: This button removes the individual existing Mac entries from the list.

  • Clear All: This button clears all the Mac addresses in the list.


Local IP List

The local IP address are the devices that are connected to the same network within your organization. This tab displays the list of all local IP addresses.

<img border=0 width=624 height=442 src="TSS%20UG%20v20_reviewed_files/image072.jpg">

This tab has 4 buttons which are as follows:

  • Add: You can add new IP address using this button. Once this button is clicked, you will see a New IP Address dialogue box. Enter the IP Address in this dialogue box and click OK.

<img border=0 width=361 height=197 src="TSS%20UG%20v20_reviewed_files/image073.png">

·         Edit: This button edits the existing entries in the list.

·         Remove: This button removes the existing individual IP entries from the list.

  • Clear All: This button clears all the IP addresses in the list.


Show Application Alert

This check box is selected by default and provides you firewall alert when an application is blocked as per an application rule.

Block Portscan

This check box is selected by default and blocks all Portscan attempts made by Hackers.

Clear Alert Cache

You can click this button to clear all the information, such as previous actions taken or blocked programs stored in the firewall's cache.

<img border=0 width=423 height=348 src="TSS%20UG%20v20_reviewed_files/image074.png">